Guide

DNSSEC for your domains

DNSSEC adds cryptographic signatures to DNS so resolvers can detect tampering. On NovaMX, authoritative DNS for your zone is signed when DNSSEC is enabled for the domain, for any TLD we host.

What you protect

Without DNSSEC, an attacker could redirect visitors or mail by publishing false DNS answers. With DNSSEC, validating resolvers reject answers that do not match the signed chain of trust from the root to your domain.

Parent DS at any registry or registrar

For every TLD, the parent registry (or your registrar acting for it) must publish a DS record that matches your zone DNSKEY. NovaMX signs your zone on authoritative DNS and helps you publish or update that DS when you enable or rotate DNSSEC in My NovaMX. For .nl, SIDN is the registry; other TLDs use their own registries with different DS submission screens, but the chain of trust is the same idea.

Typical steps in My NovaMX

  1. Open the domain in My NovaMX and enable DNSSEC if it is not already active.
  2. Review the DS digest shown in the portal and confirm publication at the registrar when prompted.
  3. Wait for DNS propagation (usually minutes to a few hours), then run an external DNSSEC test.
  4. After key rollovers, follow the portal guidance so old and new DS records overlap during the transition.

Verify externally

Run the Internet.nl website test or a DNSSEC debugger to confirm the chain is valid end to end. Domain checks in My NovaMX highlight DNSSEC gaps when your package includes them.

Registry differences

Parent registries differ in how you submit DS data (portal forms, EPP, or registrar automation). The NovaMX portal shows the digest and instructions for your TLD. If the domain is registered elsewhere while NovaMX hosts DNS, you still paste or confirm the same DS values at that registrar.

Common mistakes

Removing NovaMX nameservers while a DS record still points at your old signed zone breaks validation. Skipping the overlap period during key rollover can make the domain unreachable for validating resolvers. Enabling DNSSEC at the registrar without matching keys in the NovaMX zone causes SERVFAIL for signed queries.

When you are stuck

Check the DNSSEC status card in My NovaMX for the next action. Run Internet.nl after propagation waits. Open Messages if DS publication at an external registrar fails repeatedly.